Crypto Ticker:
sysadmin from 4sysops.com

GitSpawn lets poisoned repositories run code through AI coding agents

IT News
Wednesday at 16:07
4 Views
0 Comments
GitSpawn lets poisoned repositories run code through AI coding agents

A repository’s own `.git/config` can still trigger attacker-controlled code through Claude Code, Codex, Cursor, goose, and other AI coding agents before trust prompts, authentication, model calls, or tool approvals occur. Manifold Security’s GitSpawn research found eight flaws across seven agents; fixes are available for several tools, but Hermes Agent, Qwen Code, Grok Build, and a second Claude Code path remained vulnerable during September testing. Source

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!